Back to skill

Security audit

小红书爆款文案助手

Security checks for vulnerabilities and agentic risk

Overview

This is a hosted Xiaohongshu copywriting helper that sends user-provided copywriting inputs to the AI Skills API, with no evidence of destructive, hidden, or persistent behavior.

Install only if you are comfortable sending topics, audience details, selling points, account persona, and any enabled profile context to the AI Skills service. Keep AISKILLS_API_KEY private, leave AISKILLS_BASE_URL pointed at a trusted HTTPS service, and avoid submitting secrets, unpublished confidential plans, or regulated personal data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run.py:24
Finding

Unvalidated API Base URL Can Expose Credentials and User Content

Content
View full analysis

Vulnerability Details

File Location: scripts/run.py:24-39, 76-83
Vulnerability Type: Arbitrary outbound endpoint and credential disclosure
Risk Level: Medium

Vulnerable Code

python
def build_base_url():
    return os.getenv("AISKILLS_BASE_URL", DEFAULT_BASE_URL).rstrip("/")

def build_headers():
    api_key = os.getenv("AISKILLS_API_KEY", "").strip()
    tenant_id = os.getenv("AISKILLS_TENANT_ID", "default").strip() or "default"
    if not api_key:
        fail("AISKILLS_API_KEY is required")
    return {
        "Content-Type": "application/json",
        # Cloudflare blocks urllib's default Python user agent for this endpoint.
        "User-Agent": "ai-skills-runner/1.0 (+https://ai-skills.ai)",
        "Accept": "application/json",
        "X-API-Key": api_key,
        "X-Tenant-Id": tenant_id,
    }
python
def request_json(method, path, payload):
    body = json.dumps(payload).encode("utf-8")
    req = urllib.request.Request(
        f"{build_base_url()}{path}",
        data=body,
        method=method,
        headers=build_headers(),
    )
    try:
        with urllib.request.urlopen(req, context=SSL_CONTEXT) as response:
            return json.loads(response.read().decode("utf-8"))

Technical Analysis

The request origin is taken directly from the AISKILLS_BASE_URL environment variable without validation of its scheme, hostname, port, or trust relationship. Every request to the resulting URL includes the AISKILLS_API_KEY and AISKILLS_TENANT_ID authentication headers. The request body also includes user-provided copywriting inputs.

Consequently, a party capable of controlling the runner's environment can redirect requests to an arbitrary server. The implementation does not require HTTPS, enforce an approved hostname, or conditionally attach credentials only to the expected API origin. HTTPS certificate verification protects connections to the hostname selected by the environment variable, but it does not e ...[truncated 1777 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the execution endpoint to https://ai-skills.ai when endpoint customization is not operationally required.
  2. If customization is required, parse the configured URL and enforce:
    • The https scheme.
    • An explicit allowlist of trusted hostnames.
    • Approved ports only.
    • No embedded user information.
    • No query string or fragment.
  3. Attach X-API-Key and X-Tenant-Id only after confirming that the final request origin exactly matches an approved origin.
  4. Disable automatic cross-origin redirects or validate every redirect target before forwarding authentication headers.
  5. Reject plain HTTP endpoints to prevent credentials and content from being transmitted without transport encryption.
  6. Separate development endpoint overrides from production behavior and require an explicit, clearly named development mode for non-production hosts.
  7. Use short-lived, narrowly scoped credentials where supported, and rotate any key suspected of having been used with an untrusted endpoint.
  8. Add automated tests covering malicious schemes, unapproved domains, embedded credentials, unexpected ports, and redirect-based credential leakage.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares required environment variables and documents calling an external API, but it does not define any explicit tool scope such as allowed tools or permissions. That creates an over-broad execution surface where a host agent may grant env and network access implicitly, increasing the chance of unintended secret exposure or network egress beyond what users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger description is broad and ambiguous, covering generic content-creation questions like '小红书怎么写才有人看' without clear activation boundaries. In an agent environment, this can cause the skill to auto-activate for loosely related requests and route user content to external processing when the user did not explicitly intend to use this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The usage scenarios describe activation in very broad terms for creators, marketers, and media users needing analysis or optimization results. This overlap with common writing-assistance requests increases the risk of accidental invocation and unnecessary transmission of user-supplied business or marketing materials to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly states that runner parameters are sent to the AI Skills API, but it does not present a clear user-facing warning that their input will leave the local agent context and be shared with a third party. If users provide drafts, audience data, product plans, or other sensitive materials, this can result in unintended data disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The display name, short description, and default prompt are written in Chinese, which implies a fixed language/locale experience without any opt-in or documented regional justification. This can violate language or locale policy when users are not given a choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation but provides no bounded activation conditions, examples, or guardrails to constrain when it should be selected. This can cause the agent to invoke the skill in unrelated conversations, increasing the chance of unintended prompt injection exposure, privacy leakage into the skill context, or unwanted autonomous behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema uses Chinese for user-facing labels, descriptions, and defaults throughout the form, such as the advanced settings label and field titles/options. Because the file provides no indication that Chinese is optional or that the skill is intentionally region-specific, it appears to impose a specific language/locale without user choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation question "小红书怎么写才有人看?" is broad natural-language phrasing that can overlap with ordinary user conversation, increasing the chance of accidental or opaque skill invocation. In an LLM-routed environment, this can cause the system to trigger the skill when the user intended general advice, which may unexpectedly send user input and profile context to the external execution path.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

For a skill framed as a Xiaohongshu copywriting assistant, accessing deployment credentials and tenant routing information is not part of the user-facing purpose described in the manifest. This capability exists to authenticate against backend infrastructure, which is operationally sensitive and should be explicitly declared if relevant to the skill’s scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest describes a helper for generating summaries, diagnoses, action suggestions, and reusable copywriting deliverables, but this file actually packages user parameters and sends them to a remote API for execution. While remote inference can be an implementation detail, the code also handles billing responses and async job polling against a hosted service, which is materially broader operational behavior than the manifest communicates.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill description, invocation context, parameter guidance, and examples are presented only in Chinese, with no indication that users may choose another language or that the language restriction is intentional and required. This can constitute a language-policy issue when a skill implicitly enforces a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

User-facing fields such as the question, skill name, labels, and descriptions are presented only in Chinese, with no indication that the user can choose another language or locale. This can violate language/locale policy when a skill implicitly forces a specific language without documented opt-in or a region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP 402 handling hard-codes a Chinese-language message for insufficient billing balance. This is a natural-language locale policy issue because the script does not offer any user language selection or document that the tool is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.